Advertisement
Meta AI Chatbot Exploited for Instagram Account Takeover
Attackers manipulate Meta's AI support chatbot to reset Instagram passwords and hijack accounts via unauthorized email updates and location spoofing.
Shrinking IAM Attack Surface via Identity Visibility Platforms (IVIP)
Enterprise security teams must tackle Identity Dark Matter using IVIP to eliminate blind spots in fragmented identity and access management environments.
Misconfigured MSAL for Android Exposes Microsoft Account Tokens
A vulnerability in the Microsoft Authentication Library for Android allowed unauthorized apps to intercept OAuth tokens, impacting billions of users.
Meta AI Support Abuse Leads to Instagram Account Hijacking
Attackers exploit Meta AI support tools to bypass traditional security and hijack Instagram profiles, leaving legitimate users locked out of their accounts.
Dashlane Brute-Force Attack: Safeguarding Encrypted Password Vaults
Dashlane reports a brute-force attack resulting in the download of encrypted user vaults. Learn about the impact and remediation steps for this identity threat.
Dashlane Brute-Force Attack: Mitigation for Stolen Encrypted Vaults
Dashlane confirms a brute-force attack where fewer than 20 personal vaults were downloaded. Analyze the technical impact and mitigation strategies for users.
Dashlane Account Lockouts: Brute-Force Attacks Target Password Manager Users
Dashlane users are experiencing widespread account lockouts due to brute-force attacks. Learn how credential stuffing impacts password managers and mitigation strategies.
Meta AI Support Bot Exploited for Instagram Account Takeovers
Hackers manipulated Meta's AI support assistant to bypass authentication and seize high-profile Instagram accounts, including government entities.
Google Chrome DBSC: Preventing Account Takeover via Cookie Theft
Google Chrome rolls out Device Bound Session Credentials (DBSC) to protect users from session hijacking by cryptographically binding cookies to hardware.
Optimizing Active Directory Security with Modern Password Policies
Learn how to implement NIST-compliant Active Directory password policies using passphrases and breached password protection to reduce identity-based risks.
ITDR: Defending Against Credential-Based Attacks in 2024
Analysis of Identity Threat Detection and Response (ITDR) necessity and market leadership in protecting hybrid enterprise environments from identity theft.
Windows Server 2016 DC Lookup Failures: KB5037763 Mitigation Guide
Microsoft confirms a regression in Windows Server 2016 causing LSASS crashes and domain controller lookup failures after the May 2024 security update.
Akamai Acquires LayerX: Enterprise Browser Security Trends 2024
Akamai's acquisition of LayerX highlights the strategic shift toward secure enterprise browsers to mitigate SaaS risks and protect unmanaged devices.
RFID Vulnerabilities: Analyzing Ghost on the Wire Security Risks
Technical analysis of passive RFID tag security vulnerabilities including cloning and relay attacks revealed in the Ghost on the Wire research.
AI Agent Identity Security: Budget Dynamics & Governance Priorities
New Omdia research reveals AI agent proliferation is fundamentally altering enterprise identity security budget dynamics, demanding distinct governance and management
GCP API Keys Remain Active Post-Deletion: A 23-Minute Security Flaw
A security researcher found Google Cloud Platform (GCP) API keys stay active for 23 minutes post-deletion, posing a significant risk.
Securing Identity Attack Paths: Protecting Cached AWS Credentials
Attackers exploit cached AWS access keys to achieve lateral movement. Learn how identity-based attack paths expose 98% of cloud entities and how to defend.
Protecting Identities from Infostealers: Session Hijacking Mitigation
Learn how infostealers like Lumma bypass MFA via session token theft and discover technical strategies for implementing device-bound authentication.
Zero Trust: Why Device Security is Essential Beyond Identity
Identity-only security fails against stolen tokens and compromised devices. Learn why robust device security is critical for effective Zero Trust strategies.
Bypassing AI-Based Age Verification via Facial Obfuscations
Research reveals that AI-driven age estimation systems can be bypassed using physical facial alterations, highlighting flaws in biometric verification models.
Active Directory Post-Breach Persistence: Why Password Resets Fail
Explaining why password resets fail to evict attackers from Active Directory due to Kerberos ticket persistence and MSV1_0 credential caching mechanisms.
ICE Developing Smart Glasses with Integrated Facial Recognition
ICE is developing smart glasses with real-time facial recognition linked to federal databases, raising significant privacy and technical security concerns.
Securing Human, Machine, and AI Identities in Modern Environments
Explore the shift from human-centric IAM to managing machine and AI identities. Learn strategies for visibility and risk reduction in hybrid cloud.
Defeating Persistent OAuth Token Risks in Google and Microsoft Apps
Learn how persistent OAuth tokens create backdoors in AI tools and productivity apps. Discover strategies to detect and remediate long-lived token exposure.